Trending

#Deserialization

Latest posts tagged with #Deserialization on Bluesky

Latest Top
Trending

Posts tagged #Deserialization

- YouTube
- YouTube Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

💣 CLIXML #deserialization in #PowerShell isn't harmless…
At #PSConfEU 2025, Alexander Andersson showed how it enables:
✔ Lateral movement
✔ Privilege escalation
✔ Guest-to-host VM breakouts
🎟️ Early bird 2026 tickets → psconf.eu
#Security #CLIXML

2 1 0 0
Preview
High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478) › Searchlight Cyber This morning, an advisory was released for Next.js about a vulnerability that leads to RCE in default configurations, with no prerequisites. The root cause of this issue lies in React Server Component...

High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478):

slcyber.io/research-cen...

#exploit #exploitation #infosec #informationsecurity #cve #rce #hacking #deserialization

0 0 0 0
Preview
Making Serialization Gadgets by Hand - .NET | Blog | VulnCheck Creating a language-native .NET source for deserialization gadgets

Making Serialization Gadgets by Hand - .NET:

www.vulncheck.com/blog/making-...

#dotnet #infosec #deserialization #hacking #programming #exploit #exploitation

1 0 0 0

Active exploitation observed for WSUS deserialization bug CVE-2025-59287; report from a customer alert on Windows Server Update Services noted by Bas van den Berg. Limited IoCs published. #CVE-2025-59287 #WSUS #deserialization https://bit.ly/49q0nhx

0 0 0 0
Post image

Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236):

slcyber.io/assetnote-se...

#infosec #cybersecurity #deserialization #rce #exploit #exploitation #cve

2 0 0 0
Original post on esecurityplanet.com

Critical Apache ActiveMQ Flaw Lets Attackers Run Code Remotely A flaw in Apache ActiveMQ’s .NET client lets attackers run code remotely, risking full system compromise for unpatched users. The po...

#News #Threats #.NET #security #Apache #ActiveMQ […]

[Original post on esecurityplanet.com]

0 0 0 0
SolarWinds logo over world map silhouette

SolarWinds logo over world map silhouette

🚨 Patch bypass alert for SolarWinds Web Help Desk. Unauth attackers can run commands via AjaxProxy deserialization — a new bypass of CVE-2024-28988 (itself a bypass of 28986). Patch fast and lock down access.

🔗 basefortify.eu/cve_reports/...

#SolarWinds #RCE #Deserialization

1 0 0 0

Leaked #secrets + a #ViewState weakness gave attackers a foothold to pivot and escalate inside Sitecore. It's a real-world example of App weakness exploitation in action 🧵2/4

#AppSec #DotNet #Deserialization

0 0 1 0
- YouTube
- YouTube Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.

💣 CLIXML #deserialization in #PowerShell isn't harmless…
At #PSConfEU 2025, Alexander Andersson showed how it enables:
✔ Lateral movement
✔ Privilege escalation
✔ Guest-to-host VM breakouts
🎟️ Early bird 2026 tickets → psconf.eu
#Security #CLIXML

1 3 1 0
Video

Using JsonPropertyName to map Json to Class C# Tip #42

How to use the JsonPropertyName attribute in C# to map mismatched JSON fields (like id) to class properties (like UniquePostId) during deserialization. #CSharp #JSON #Deserialization #HttpClient #JsonPropertyName #DataMapping #WebAPI #DotNet

0 0 0 0

[oss-security] CVE-2025-48734: Apache Commons BeanUtils: PropertyUtilsBean does not suppresses an enum's declaredClass property by default


www.openwall.com ->

I wonder if the now restricted behavior is useful for #deserialization gadgets (I
1/2

0 0 1 0
Preview
Serialization and Deserialization In Java — What is SerialVersionUID and When to Regenerate It Serialization and Deserialization In Java, SerialVersionUID Generation and How to Auto Add It in IntelliJ IDEA

Serialization and Deserialization In Java — What is SerialVersionUID and When to Regenerate It #java #serialization #deserialization #serialversionuid #intellij #intellijidea senoritadeveloper.medium.com/serializatio...

1 1 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

1 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Post image

CISA Warns of Actively Exploited Adobe ColdFusion and Oracle Agile PLM Vulnerabilities The Cybers...

thecyberexpress.com/cisa-adds-cve-2017-3066-...

#Firewall #Daily #Cyber #News #Vulnerabilities #Adobe #ColdFusion […]

[Original post on thecyberexpress.com]

0 0 0 0
Original post on stackoverflow.com

Is there a simple recursive analogue of this breadth-first binary tree deserialization function i...

stackoverflow.com/questions/79413187/is-th...

#haskell #functional-programming #deserialization #binary-tree […]

0 0 0 0
Original post on stackoverflow.com

Is there a simple recursive analogue of this breadth-first binary tree deserialization function i...

stackoverflow.com/questions/79413187/is-th...

#haskell #functional-programming #deserialization #binary-tree […]

0 0 0 0
Preview
Built-in Way of Working with JSON in Unity Code JSON (JavaScript Object Notation) is a widely used data interchange format, and integrating it into Unity can be powerful for handling configurations, saving game progress, o...

Built-in Way of Working with JSON in Unity Code #Unity #Programming #Tutorial #Json #Structure #Serialization #Deserialization #Arrays #Objects #Csharp #Development #Coding #Data #Format

0 0 0 0
Preview
GitHub - Spix0r/django-rce-exploit: A Python tool for exploiting Django RCE via deserialization vulnerabilities in session cookies, allowing remote code execution through forged cookies. A Python tool for exploiting Django RCE via deserialization vulnerabilities in session cookies, allowing remote code execution through forged cookies. - Spix0r/django-rce-exploit

I've just dropped a #Python tool to exploit #Django RCE by leveraging #deserialization in session cookies.

It forges a malicious cookie that executes system commands remotely.

🔗 Check it out here: github.com/Spix0r/djang...

#CyberSecurity #BugBountyTools #RCE #BugBounty #Exploit #BugBountyTips

1 0 0 0
The sorry state of Java deserialization I’ve been on a bit of a frustration-driven quest to solve a problem I frequently encounter working on the search engine, that is, reading data from disk. You’d think this would be a pretty basic thing, but doing this in a way that is half-way performant is surprisingly hard and requires avoiding basically all the high level tools at your disposal. There’s a common sentiment that modern hardware is fast, so this may not matter, but we aren’t speaking a 30% performance hit, the the question is how many orders of magnitude you’re willing to forego.

The sorry state of Java deserialization

#deserialization #java

www.marginalia.nu/log/a...

1 1 0 0
Preview
GreyNoise Labs - Panic!! At the YAML An overview of SnakeYAML deserialiation vulnerabilities (CVE-2022-1471) - how it works, why it works, and what it affects

Before the break, I started looking at CVE-2022-1471 in Confluence et al, which led me learn about SnakeYAML deserialization. It was quite the ride, full of open source drama and related vulns. I wrote it all up in this blog post!

#vuln #vulnerability #poc #java #deserialization #snakeyaml #yaml

4 3 0 0